Educause Security Discussion mailing list archives

Local Administrator Accounts


From: "Nipper, Johnny R." <Nipperj () UNCW EDU>
Date: Thu, 10 Jul 2008 16:16:40 -0400

I am interested in hearing how everyone manages local administrator
accounts of client machines on their network.  Do you leave them enabled
or disabled?  For those who allow local administrator accounts, do you
use unique passwords?  Are you using a homogeneous account across the
network?  If the latter is true, how do you guarantee AAA?  For example,
what would stop a cracker with access to one machine to use his cracked
hashes across the network?

 

-Johnny


Current thread: